BUG #4195
openDescription
Issue Description
On the Admin Profile → Reset Password page, when an email address associated with an agency account is entered, the system returns the error message “You do not have access to the administration panel.”
This message may allow account type enumeration by revealing internal access control information, which is not desirable from a security perspective.
Module / Page
Admin Profile → Reset Password
Module Section
Password Reset / Error Messaging
Screen Size
Desktop
Tested By
Tasfia Zaima
Steps to Reproduce¶
- Navigate to the Reset Password page of admin.
- Enter an email address associated with an agency account.
- Click the Submit / Reset Password button.
- Observe the error message displayed: “You do not have access to the administration panel.”
Expected Result
The Reset Password flow should return a generic message (e.g., “If an account exists, password reset instructions will be sent”) without revealing account type or access level.
Actual Result
The system displays the message “You do not have access to the administration panel.”, exposing internal access control details.
Attachments
PoC
Types of Issue
Functional Issue
Root Cause:
Impacted Area: